Legal

Privacy Policy

Effective: 22 July 2026 · Version 1.3 · Provider: Samuel Ehalaiye, New Zealand · Contact: support@quvex.app

1. Who we are

Quvex ("the app", "we", "us") is provided by Samuel Ehalaiye, based in New Zealand. Contact us about privacy at support@quvex.app. Quvex has no account and we do not receive your personal data. The data that leaves your device at all is limited: your device's IP address when the app loads the partner directory or community content, and — only when you ask the app to look up a song — the song title and artist you type, which go to Apple's iTunes Search service. Both are explained in §4. Optional voice dictation uses your device's microphone, but the audio is transcribed by your phone's on-device speech recognition and does not leave your device (see §3). If your phone supports the optional AI writing polish, its Google ML Kit component reports usage and performance metrics to Google — never what you write (see §3).

2. No account — everything stays on your device

There is no sign-in, no cloud, no sync, and no back-up to any server we run. The information you enter is stored only on your own device; it never leaves your phone and is never sent to us, so we cannot see, store, share, or sell it.

3. What the app stores on your device

This is held in the app's local storage and protected by your device's security. You can delete individual entries or whole profiles, or clear all app data, from within the app; uninstalling also removes it. We hold no copy. We run no server that stores your personal data, so there is no retention period to apply: your information lives only on your device until you delete it or uninstall Quvex, and there is nothing for us to retain or delete on your behalf. If you choose the phone-to-phone transfer (QR or local Wi-Fi), your data moves directly between your two devices; it does not pass through us or any server we run.

4. Partner directory and community content

To show occasional, labelled local-business suggestions — and community-tuned song ideas and short community-written messages — the app loads public content from our hosting provider (Google Firebase / Cloud Firestore): the partner directory, a per-language song list, and community messages. Like any internet request, these lookups include your device's IP address and the app's public project identifier, but no cycle data, symptoms, profiles, city, or account. Each is an anonymous, read-only lookup — not signed in, carrying no profile of you, never used for analytics or advertising — and the content is cached on your device so the app keeps working offline. If you report a community message from within the app, the app sends only the report itself: a random device tag (so one device counts once), the optional short reason you type, and the time — no account and nothing that identifies you. (The app also checks Google Play for app updates using Google's own mechanism, which sends us nothing about you; see §7.)

When you add a song, or ask the app to find one she plays, the app looks that song up on Apple's public iTunes Search service to fetch its cover art — and, when the match is uncertain, a few candidate results so you can choose the right one. That lookup sends the song title and artist you typed over a secure (HTTPS) connection, with no account and nothing that identifies you. It runs only when you start it, works the same whether or not you use any other online feature, and carries no cycle data, symptoms, profiles, or city. Apple receives only that search text and your IP address, and handles them under Apple's own privacy policy; the result is kept only on your device. After you add a song, its artwork may load from Apple's image servers whenever the app displays it. (The curated songs the app already knows ship with their artwork inside the app, so those load with no connection at all.) This is one of only two times the app sends text you have typed off your device — the other is the optional report reason described above.

Partner listings are community-verified, not vetted by us. Separately, on the Quvex website (not the app), you can choose to anonymously vouch for or up/down-vote a partner listing, vote on songs, or write and vote on short community messages. If you do, we store only your vote, vouch, or message and a random tag we keep in your browser so each browser counts once — no account, no name, no email, and nothing that identifies you; you can clear the tag any time by clearing your browser storage. Posts and votes from the same browser share that tag, so they can be linked to each other but never to you. A message you post is public and shown to other users and in the app — please don't include personal information in it. To have a community message you posted removed, email support@quvex.app quoting the message's ID. We use these signals only to rank and curate community content, never for advertising. The Quvex app itself never sends any of this — its only writes are the message reports described above.

5. Information about another person

Quvex is a companion app, so the cycle information you enter is often about someone else — which is sensitive health information that belongs to them. Because everything stays on your device and we never receive it, you use the app for your own personal/household purposes and we are not a holder or "controller" of that information. You may only add a profile for a person who knows and agrees, and both of you must be 18 or over (§10). If someone asks you to stop and delete their data, do so — it is removed from your device, and we hold no copy.

6. How Quvex stays free

Quvex is completely free: every feature is available to everyone, with no fees, subscriptions, in-app purchases, or ads. The developer funds it himself, and the running cost is minimal. We earn no commission from partner businesses and have no plans to — partner recommendations are merit-based, never paid placement, and we take no cut if you visit or buy from one. We do not sell or share your personal information and do not run a data-driven advertising business.

7. Processors, transfers, and legal basis

Our hosting provider, Google Firebase (Cloud Firestore), serves the public partner directory and community content (§4) as our processor; no personal data of yours is sent to it. When you look up a song (§4), the app queries Apple's public iTunes Search API directly; Apple then receives the song title and artist you typed, plus your IP address, as an independent provider under Apple's own privacy policy — not as our processor, and never any cycle data. Where that request reaches Apple outside the EEA/UK, it relies on Apple's own transfer safeguards. We include no analytics, advertising, tracking, or crash-reporting components, use no sign-in, and request no location permission. On devices that support the optional on-device AI writing polish, Google's ML Kit component sends Google operational metrics about that feature's performance and use (never your text or cycle data), as described in §3. The app also checks Google Play for app updates using Google Play's own update mechanism; this carries no Quvex data about you. Because we never receive your cycle or profile data, there is no server of ours that could be breached to expose it.

These content requests reach Google's australia-southeast1 (Sydney) region, carrying your IP address but no other personal data. For EU/EEA/UK users this is a transfer outside the EEA/UK to a country without an adequacy decision; it is covered by the European Commission's Standard Contractual Clauses (and UK Addendum) in Google's terms, and Google is certified under the EU–US Data Privacy Framework for any US processing. Where we rely on a legal basis under the EU/UK GDPR for these requests, it is our legitimate interest (Art 6(1)(f)) in operating the free directory and community features. We have weighed that interest against your rights (a legitimate-interests assessment): an IP address may itself be personal data, but it is transient network metadata, we build no profile and do not use it to identify or track you, and the requests happen only while you use the app — so our interest does not override your privacy. You can object to this processing simply by keeping the app offline (it works fully without a connection) or not using those features. Your cycle data — special-category health data under GDPR Article 9 — is processed by you, on your device, for personal/household purposes; we are not its controller. We are the controller only of those content requests carrying your IP and of the anonymous community signals described in §4, and of nothing else.

8. Data security and breach notification

Your cycle data, symptoms, and profiles are protected by your device's own security and by the app's privacy features (such as a secure screen and neutral notifications). Because everything stays on your device and we keep no central copy, there is no store of ours that could be breached to expose it. In the unlikely event that a breach of the limited request data we do handle (§7) were likely to cause you serious harm, we would notify you and the New Zealand Privacy Commissioner as the Privacy Act 2020 requires.

9. Your rights

Because your information stays on your device, you can view, correct, delete, and export it in the app at any time. Depending on where you live — including under New Zealand's Privacy Act 2020, the EU/UK GDPR, California's CCPA/CPRA, the Washington, Nevada and Connecticut consumer-health laws, Canada's PIPEDA/Quebec Law 25, Brazil's LGPD, and similar laws — you have rights to access, correct, delete, and port your personal data, and to opt out of any sale or sharing. We do not sell or share your data and hold none of it, so these are satisfied on your device. You also have the right to object to the processing we do carry out — the content requests (§7) and the anonymous community signals (§4) — which you can exercise simply by keeping the app offline or not using those features. We collect no "consumer health data" and no precise location, share none, and do not geofence health facilities, so the United States consumer-health laws have nothing of yours to reach. To make a request, contact support@quvex.app; you may also complain to your local regulator (for example the NZ Privacy Commissioner, the UK ICO, or the Irish Data Protection Commission). To have a community message you posted removed, email support@quvex.app quoting the message's ID.

10. Children

Quvex is only for adults aged 18 or over and is not directed to children. You must be 18+ to use it, and you must not enter information about anyone under 18. We do not knowingly collect children's data (we collect no one's), and we are not aware of any minor's data reaching us; if you have a concern, contact support@quvex.app.

Your information exists only on your own device and is not held on any server we control, so we have nothing to disclose in response to a subpoena or other legal request.

12. Changes

If we change this policy we will post the updated version here and update the effective date above. For changes that materially affect your rights or how your data is handled, we will also show an in-app notice the next time you open Quvex, not only post it here. We will not introduce any feature that collects your personal data on a server (such as an account, back-up, or sync) without first updating this policy and obtaining your consent where the law requires it. This policy is written in English; if we provide a translation and it differs, the English version prevails.

13. Contact

Questions or requests: support@quvex.app. See also our Terms of Use.